Cloud Storage versioning is disabled

Review earlier object version retention and recovery policies in Cloud Storage.

Description

Cloud Storage versioning retains overwritten or deleted live objects as noncurrent versions, helping recover from corruption or mistakes. Decide whether to use it according to the recovery needs of logs, backups and production data.

Other recovery features, such as soft delete, can apply even when versioning is disabled. Versioning does not replace audit logs that identify who made a change or every need for a separate backup.

Potential impact

  • Without the required recovery points, restoring overwritten or deleted objects can be difficult.
  • Keeping unnecessary earlier versions indefinitely can increase storage costs.

Remediation

  • Set versioning.enabled: true on buckets that need to retain earlier versions.
  • Review soft delete and lifecycle policies together, define retention periods, restrict permissions to delete earlier versions and test restoration.

Examples

These excerpts use the retired Deployment Manager format. Manage the same policy with a supported tool and supply the actual bucket name and required settings.

Before

yaml
resources:
  - name: bucket
    type: storage.v1.bucket
    properties:
      storageClass: STANDARD
      location: EUROPE-WEST3

After

yaml
resources:
  - name: bucket
    type: storage.v1.bucket
    properties:
      storageClass: STANDARD
      location: EUROPE-WEST3
      versioning:
        enabled: true

Explanation:

  • Before: Versioning is omitted. Check the effective retention policies and recovery options for an existing bucket.
  • After: Versioning is enabled. It does not prevent bucket deletion or restore data that was permanently deleted earlier.

References